PT-2025-36032 · Unknown · Disclaimersparserimpl.Java

Published

2025-09-01

·

Updated

2025-09-05

·

CVE-2025-26454

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DisclaimersParserImpl.java (affected versions not specified)
Description A flaw exists in the validateUriSchemeAndPermission function within the DisclaimersParserImpl.java component that may allow unauthorized access to data belonging to other users due to a confused deputy condition. Successful exploitation of this issue could result in local privilege escalation without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ASB-A-299928772
BDU:2025-11689
CVE-2025-26454

Affected Products

Disclaimersparserimpl.Java